An organisational capability or dedicated unit responsible for the planning, execution, and reporting of audit activities within or on behalf of an enterprise. The audit function provides independent assurance over risk management, internal controls, and governance processes, acting as a critical third line of defence in enterprise risk frameworks.
Content
- Internal audit as a structured organisational function emerged formally in the mid-20th century, with the founding of the Institute of Internal Auditors (IIA) in 1941 marking a professionalisation milestone. Initially focused on financial records verification, internal audit expanded through the 1980s and 1990s into operational auditing, IT auditing, and risk-based auditing methodologies. The COSO Internal Control–Integrated Framework (1992, updated 2013) and the Three Lines of Defence model became foundational reference architectures that positioned the audit function as an independent assurance provider.
- The audit function operates across a lifecycle: annual risk assessments to prioritise engagements, fieldwork planning, evidence collection using data analytics and sampling, findings documentation, management responses, and periodic reporting to the board’s audit committee. Technology-enabled continuous auditing now allows the function to monitor control effectiveness on an ongoing basis rather than relying exclusively on periodic point-in-time reviews. Audit management software platforms track findings, action plans, and remediation status, creating structured accountability loops.
- In large enterprises the audit function typically subdivides into specialisations: financial and controls auditing, information-technology auditing, cybersecurity auditing, operational auditing, and, increasingly, ESG and sustainability auditing. External audit firms provide additional assurance over statutory financial statements and, via agreed-upon procedures engagements, targeted assessments of specific controls. Regulators impose independence requirements to prevent conflicts of interest between advisory and assurance roles within the same firm.
- By 2025 the audit function is undergoing significant transformation driven by AI-assisted workpaper analysis, natural-language processing applied to contract and policy review, and automated anomaly detection over transactional data. These tools raise audit coverage whilst reducing manual effort. Simultaneously, boards are demanding AI-specific audit capabilities — assessing model governance, training-data lineage, and algorithmic bias — that require the function to recruit technologists and data scientists alongside traditional accountants and auditors.